1 of 8

WLCG IAM Deployment at CERN

pre-GDB

Authored by Hannah Short

November 8th 2021

1

2 of 8

Deployments

2

https://cms-auth.web.cern.ch

https://atlas-auth.web.cern.ch

https://alice-auth.web.cern.ch

https://lhcb-auth.web.cern.ch

TBC

3 of 8

Infrastructure

Leveraging CERN’s infrastructure as far as possible.

Scalable deployment on Openshift.

3

CERN Database on Demand (MySQL)

CERN’s PaaS, Openshift (OKD4)

vo-auth.web.cern.ch

CERN Gitlab for config (kustomize)

Prod

Dev

vo-auth-dev.web.cern.ch

Docker Hub for images (will be moved to CERN docker)

Deploy with Kubectl

hr-db-api.web.cern.ch

HR DB

CERN Logs

4 of 8

Authentication

  • LHC VOs have two login options
    • Certificate login
    • CERN SSO
  • Expectation that users will authenticate with CERN SSO for registration and can add certificate later if desired
    • CERN SSO token used to validate VO membership
  • Additional admin login form hidden for normal workflows

4

5 of 8

Support

  • Supported by CERN’s Authentication Team (IT-CDA-IC)
    • 24/7 Service Desk will escalate tickets when needed
  • Working very closely with Andrea Ceccanti
  • TBC whether WLCG/CERN security team will have direct access as administrators or whether blocking API required

5

6 of 8

Wish List

  • Shared base config for IAM instances
  • Htgettoken and Vault installation for WLCG IAMs integrated with CERN Kerberos (timeline TBC)

6

7 of 8

Next Steps

  • Complete full development infrastructure
    • Ideally with automatic deployment with gitlab CI�
  • Complete production readiness checklist
    • Stress tests
    • Incident response procedures (plus tests)
    • Monitoring
    • … etc :)

7

8 of 8

Questions?

8

WLCG AuthZ WG

12/07/17